User's Manual
408
Document #: LTRT-10375
Mediant 500 MSBR
Parameter
Description
The corresponding global parameter is
SRTPTxPacketMKISize.
SBC Enforce MKI Size
sbc-enforce-mki-size
[IpProfile_SBCEnforceMKISize]
Enables negotiation of the Master Key Identifier (MKI) length for
SRTP-to-SRTP flows between SIP networks (i.e., IP Groups).
This includes the capability of modifying the MKI length on the
inbound or outbound SBC call leg for the SIP entity associated
with the IP Profile.
[0] Don't enforce = (Default) Device forwards the MKI size as
is.
[1] Enforce = Device changes the MKI length according to the
settings of the IP Profile parameter, MKISize.
SBC Media Security Method
sbc-media-security-method
[IpProfile_SBCMediaSecurityMet
hod]
Defines the media security protocol for SRTP, for the SIP entity
associated with the IP Profile.
[0] SDES = (Default) The device secures RTP using the
Session Description Protocol Security Descriptions (SDES)
protocol to negotiate the cryptographic keys (RFC 4568). The
keys are sent in the SDP body ('a=crypto') of the SIP
message and are typically secured using SIP over TLS
(SIPS). The encryption of the keys is in plain text in the SDP.
SDES implements TLS over TCP.
[1] DTLS = The device uses Datagram Transport Layer
Security (DTLS) protocol to secure UDP-based media
streams (RFCs 5763 and 5764). For more information on
DTLS, see SRTP using DTLS Protocol.
[2] Both = SDES and DTLS protocols are supported.
Note:
To support DTLS, you must also configure the following for
the SIP entity:
TLS Context for DTLS (see Configuring TLS Certificate
Contexts on page 117). The server cipher ('Cipher
Server') must be configured to All.
IpProfile_SBCMediaSecurityBehaviourMedia configured
to SRTP or Both.
IpProfile_SBCRTCPMux configured to Supported. The
setting is required as the DTLS handshake is done for
the port used for RTP. Therefore, RTCP and RTP should
be multiplexed over the same port.
The device does not support forwarding of DTLS
transparently between endpoints (SIP entities).
As DTLS has been defined by the WebRTC standard as
mandatory for encrypting media channels for SRTP key
exchange, the support is important for deployments
implementing WebRTC. For more information on WebRTC,
see WebRTC.
Reset SRTP Upon Re-key
reset-srtp-upon-re-key
[IpProfile_ResetSRTPStateUpon
Rekey]
Enables synchronization of the SRTP state between the device
and a server when a new SRTP key is generated upon a SIP
session expire. This feature ensures that the roll-over counter
(ROC), one of the parameters used in the SRTP
encryption/decryption process of the SRTP packets is
synchronized on both sides for transmit and receive packets.
[0] Disable = (Default) ROC is not reset on the device side.
[1] Enable = If the session expires causing a session refresh
Summary of Contents for Mediant 500 MSBR
Page 2: ......
Page 33: ...Part I Getting Started with Initial Connectivity ...
Page 34: ......
Page 36: ...User s Manual 36 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 40: ...User s Manual 40 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 45: ...Part II Management Tools ...
Page 46: ......
Page 48: ...User s Manual 48 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 115: ...Part III General System Settings ...
Page 116: ......
Page 132: ...User s Manual 132 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 137: ...Part IV General VoIP Configuration ...
Page 138: ......
Page 290: ...User s Manual 290 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 306: ...User s Manual 306 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 380: ...User s Manual 380 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 454: ...User s Manual 454 Document LTRT 10375 Mediant 500 MSBR This page is intentionallty left blank ...
Page 455: ...Part V Gateway Application ...
Page 456: ......
Page 460: ...User s Manual 460 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 484: ...User s Manual 484 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 494: ...User s Manual 494 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 625: ...Part VI Session Border Controller Application ...
Page 626: ......
Page 654: ...User s Manual 654 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 656: ...User s Manual 656 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 741: ...Part VII Cloud Resilience Package ...
Page 742: ......
Page 751: ...Part VIII Data Router Configuration ...
Page 752: ......
Page 753: ......
Page 754: ......
Page 756: ...User s Manual 756 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 757: ...Part IX Maintenance ...
Page 758: ......
Page 834: ...User s Manual 834 Document LTRT 10375 Mediant 500 MSBR This page is intetnionaly left blank ...
Page 837: ...Part X Status Performance Monitoring and Reporting ...
Page 838: ......
Page 848: ...User s Manual 848 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 852: ...User s Manual 852 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 854: ...User s Manual 854 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 878: ...User s Manual 878 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 880: ...User s Manual 880 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 926: ...User s Manual 926 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 927: ...Part XI Diagnostics ...
Page 928: ......
Page 950: ...User s Manual 950 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 954: ...User s Manual 954 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 956: ...User s Manual 956 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 958: ...User s Manual 958 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 974: ...User s Manual 974 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 976: ...User s Manual 976 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...
Page 977: ...Part XII Appendix ...
Page 978: ......
Page 982: ...User s Manual 982 Document LTRT 10375 Mediant 500 MSBR This page is intentionally left blank ...